Secure onboarding and management of an ihs
Abstract
Embodiments provide secure onboarding of an Information Handling System (IHS). A rendezvous service of an onboarding system is provided with an address of an onboarding service and a token that are both to be provided to the IHS. The IHS is powered for the first time upon a transfer of the IHS to an owner of the IHS. Upon the first powering of the IHS, the IHS initiates a connection with the rendezvous service of the onboarding system. The rendezvous service provides the IHS the token and the address of the onboarding service, where the onboarding service is operated on behalf of the owner. The IHS presents the token to a firewall protecting the onboarding service. In response to the presented token being recognized by the firewall, the firewall authorizes onboarding communications by the IHS with the onboarding service in order to configure the IHS for the owner.
Claims
exact text as granted — not AI-modified1 . A method for secure onboarding of an Information Handling System (IHS), the method comprising:
providing a rendezvous service of an onboarding system with an address of an onboarding service and a token that are both to be provided to the IHS; powering the IHS for a first time upon a transfer of the IHS to an owner; upon the first powering of the IHS, initiating, by the IHS, a connection with the rendezvous service of the onboarding system; providing, by the rendezvous service, the IHS the token and the address of the onboarding service, wherein the onboarding service is operated on behalf of the owner; presenting, by the IHS, the token to a firewall protecting the onboarding service; and in response to the presented token being recognized by the firewall, authorizing, by the firewall, onboarding communications by the IHS with the onboarding service in order to configure the IHS for the owner.
2 . The method of claim 1 , wherein the onboarding system comprises a FIDO (Fast IDentity Online) Device Onboarding (FDO) system.
3 . The method of claim 2 , wherein the token is provided to the IHS by the rendezvous service as part of a TO1 protocol FDO exchange that is initiated upon the first powering of the IHS.
4 . The method of claim 2 , wherein the token is presented by the IHS to the firewall protecting the onboarding service as part of a TO2 protocol FDO communication.
5 . The method of claim 2 , wherein the token is provided by the owner to the rendezvous service during a TO0 protocol FDO communication.
6 . The method of claim 2 , wherein the token comprises a certificate authority that must be utilized in connecting with the firewall protecting the onboarding service.
7 . The method of claim 6 , further comprising rejecting, by the IHS, the onboarding session with the onboarding service when the firewall does not utilize a connection that is secured with credentials that are validated by the certificate authority.
8 . The method of claim 1 , further comprising signing of the token by the rendezvous service, wherein the signed token includes an expiration and wherein the firewall rejects tokens with expired signatures.
9 . An IHS (Information Handling System) comprising:
one or more processors; one or more memory devices coupled to the processors, the memory devices storing computer-readable instructions that, upon execution by the processors, cause the IHS to:
power the IHS for a first time upon a transfer of the IHS to an owner;
upon the first powering of the IHS, initiate a connection with a rendezvous service of an onboarding system;
receive, from the rendezvous service, an address of an onboarding service and a token, wherein the onboarding service is operated on behalf of the owner; wherein the address and token are provided to the rendezvous service by the owner;
present the token to a firewall protecting the onboarding service; and
in response to the presented token being recognized by the firewall, utilize a connection authorize by the firewall to initiate an onboarding session with the onboarding service in order to configure the IHS for the owner.
10 . The IHS of claim 9 , wherein the onboarding system comprises a FIDO (Fast IDentity Online) Device Onboarding (FDO) system.
11 . The IHS of claim 10 , wherein the token is provided to the IHS by the rendezvous service as part of a TO1 protocol FDO exchange that is initiated upon the first powering of the IHS.
12 . The IHS of claim 10 , wherein the token is presented by the IHS to the firewall protecting the onboarding service as part of a TO2 protocol FDO communication.
13 . The IHS of claim 10 , wherein the token is provided by the owner to the rendezvous service during a TO0 protocol FDO communication.
14 . The IHS of claim 10 , wherein the token comprises a certificate authority that must be utilized in connection with the firewall protecting the onboarding service.
15 . A system for secure onboarding of an Information Handling System (IHS), the system comprising:
a rendezvous service of an onboarding system that is provided with an address of an onboarding service and a token that are both to be provided to the IHS; the IHS comprising one or more processors and one or more memory devices coupled to the processors, the memory devices storing computer-readable instructions that, upon execution by the processors, cause the IHS to
power the IHS for a first time upon a transfer of the IHS to an owner;
upon the first powering of the IHS, initiate a connection with the rendezvous service of an onboarding system;
receive, from the rendezvous service, the address of an onboarding service and a token; and
present the token to a firewall protecting the onboarding service
the onboarding service that is protected by the firewall, wherein in response to the presented token being recognized by the firewall, the firewall authorizes onboarding communications by the IHS with the onboarding service in order to configure the IHS for the owner.
16 . The system of claim 15 , wherein the onboarding system comprises a FIDO (Fast IDentity Online) Device Onboarding (FDO) system.
17 . The system of claim 16 , wherein the token is provided to the IHS by the rendezvous service as part of a TO1 protocol FDO exchange that is initiated upon the first powering of the IHS.
18 . The system of claim 16 , wherein the token is presented by the IHS to the firewall protecting the onboarding service as part of a TO2 protocol FDO communication.
19 . The system of claim 16 , wherein the token is provided by the owner to the rendezvous service during a TO0 protocol FDO communication.
20 . The system of claim 16 , wherein the token comprises a certificate authority that must be utilized in connection with the firewall protecting the onboarding service.Join the waitlist — get patent alerts
Track US2025227088A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.